ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0049×

76 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupOilRig

OilRig has used credential dumping tools such as Mimikatz to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

T1003.004
LSA Secrets
GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

T1003.005
Cached Domain Credentials
GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

T1005
Data from Local System
GroupOilRig

OilRig has used PowerShell to upload files from compromised systems.

T1007
System Service Discovery
GroupOilRig

OilRig has used sc query on a victim to gather information about services.

T1008
Fallback Channels
GroupOilRig

OilRig malware ISMAgent falls back to its DNS tunneling mechanism if it is unable to reach the C2 server over HTTP.

T1012
Query Registry
GroupOilRig

OilRig has used reg query “HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default” on a victim to query the Registry.

T1016
System Network Configuration Discovery
GroupOilRig

OilRig has run ipconfig /all on a victim.

T1021.001
Remote Desktop Protocol
GroupOilRig

OilRig has used Remote Desktop Protocol for lateral movement. The group has also used tunneling tools to tunnel RDP into the environment.

T1021.004
SSH
GroupOilRig

OilRig has used Putty to access compromised systems.

T1025
Data from Removable Media
GroupOilRig

OilRig has used Wireshark’s usbcapcmd utility to capture USB traffic.

T1027.005
Indicator Removal from Tools
GroupOilRig

OilRig has tested malware samples to determine AV detection and subsequently modified the samples to ensure AV evasion.

T1027.013
Encrypted/Encoded File
GroupOilRig

OilRig has encrypted and encoded data in its malware, including by using base64.

T1033
System Owner/User Discovery
GroupOilRig

OilRig has run whoami on a victim.

T1036
Masquerading
GroupOilRig

OilRig has used .doc file extensions to mask malicious executables.

T1036.005
Match Legitimate Resource Name or Location
GroupOilRig

OilRig has named a downloaded copy of the Plink tunneling utility as \ProgramData\Adobe.exe.

T1046
Network Service Discovery
GroupOilRig

OilRig has used the publicly available tool SoftPerfect Network Scanner as well as a custom tool called GOLDIRONY to conduct network scanning.

T1047
Windows Management Instrumentation
GroupOilRig

OilRig has used WMI for execution.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupOilRig

OilRig has exfiltrated data via Microsoft Exchange and over FTP separately from its primary C2 channel over DNS.

T1049
System Network Connections Discovery
GroupOilRig

OilRig has used netstat -an on a victim to get a listing of network connections.

T1053.005
Scheduled Task
GroupOilRig

OilRig has created scheduled tasks that run a VBScript to execute a payload on victim machines.

T1056.001
Keylogging
GroupOilRig

OilRig has employed keyloggers including KEYPUNCH and LONGWATCH.

T1057
Process Discovery
GroupOilRig

OilRig has run tasklist on a victim's machine and used infostealers to capture processes.

T1059
Command and Scripting Interpreter
GroupOilRig

OilRig has used various types of scripting for execution.

T1059.001
PowerShell
GroupOilRig

OilRig has used PowerShell scripts for execution, including use of a macro to run a PowerShell command to decode file contents.

T1059.003
Windows Command Shell
GroupOilRig

OilRig has used macros to deliver malware such as QUADAGENT and OopsIE. OilRig has used batch scripts.

T1059.005
Visual Basic
GroupOilRig

OilRig has used VBScript macros for execution on compromised hosts.

T1068
Exploitation for Privilege Escalation
GroupOilRig

OilRig has exploited the Windows Kernel Elevation of Privilege vulnerability, CVE-2024-30088.

T1069.001
Local Groups
GroupOilRig

OilRig has used net localgroup administrators to find local administrators on compromised systems.

T1069.002
Domain Groups
GroupOilRig

OilRig has used net group /domain, net group “domain admins” /domain, and net group “Exchange Trusted Subsystem” /domain to find domain group permission settings.

T1070.004
File Deletion
GroupOilRig

OilRig has deleted files associated with their payload after execution.

T1071.001
Web Protocols
GroupOilRig

OilRig has used HTTP for C2.

T1071.004
DNS
GroupOilRig

OilRig has used DNS for C2 including the publicly available requestbin.net tunneling service.

T1078
Valid Accounts
GroupOilRig

OilRig has used compromised credentials to access other systems on a victim network.

T1078.002
Domain Accounts
GroupOilRig

OilRig has used an exfiltration tool named STEALHOOK to retreive valid domain credentials.

T1082
System Information Discovery
GroupOilRig

OilRig has run hostname and systeminfo on a victim.

T1087.001
Local Account
GroupOilRig

OilRig has run net user, net user /domain, net group “domain admins” /domain, and net group “Exchange Trusted Subsystem” /domain to get account listings on a victim.

T1087.002
Domain Account
GroupOilRig

OilRig has run net user, net user /domain, net group “domain admins” /domain, and net group “Exchange Trusted Subsystem” /domain to get account listings on a victim.

T1105
Ingress Tool Transfer
GroupOilRig

OilRig had downloaded remote files onto victim infrastructure.

T1110
Brute Force
GroupOilRig

OilRig has used brute force techniques to obtain credentials.

T1112
Modify Registry
GroupOilRig

OilRig has used reg.exe to modify system configuration.

T1113
Screen Capture
GroupOilRig

OilRig has a tool called CANDYKING to capture a screenshot of user's desktop.

T1115
Clipboard Data
GroupOilRig

OilRig has used infostealer tools to copy clipboard data.

T1119
Automated Collection
GroupOilRig

OilRig has used automated collection.

T1120
Peripheral Device Discovery
GroupOilRig

OilRig has used tools to identify if a mouse is connected to a targeted system.

T1133
External Remote Services
GroupOilRig

OilRig uses remote services such as VPN, Citrix, or OWA to persist in an environment.

T1137.004
Outlook Home Page
GroupOilRig

OilRig has abused the Outlook Home Page feature for persistence. OilRig has also used CVE-2017-11774 to roll back the initial patch designed to protect against Home Page abuse.

T1140
Deobfuscate/Decode Files or Information
GroupOilRig

A OilRig macro has run a PowerShell command to decode file contents. OilRig has also used certutil to decode base64-encoded files on victims.

T1195
Supply Chain Compromise
GroupOilRig

OilRig has leveraged compromised organizations to conduct supply chain attacks on government entities.

T1201
Password Policy Discovery
GroupOilRig

OilRig has used net.exe in a script with net accounts /domain to find the password policy of a domain.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.